Draft — pending legal review This page is not published. It is drafted in the concede posture — SHY acknowledges collecting consumer health data and lists the categories, as Bumble does. The alternative is the disclaim posture used by Tinder and Hinge, which publishes the policy while stating the company does not believe it collects such data. That choice is counsel's, it changes this entire document, and Washington attaches a private right of action with treble damages to getting it wrong. Every third party named below must also be confirmed against the live vendor list before publication.

Consumer Health Data Privacy Policy

Consumer Health Data Privacy Policy

This policy applies only to residents of Washington and Nevada, and only to consumer health data as those states define it. It is separate from the SHY Privacy Policy, which governs all other personal data.

Effective date: to be set at publication.

1. Categories of consumer health data we collect, and why

2. Categories of sources

3. Categories of consumer health data that are shared

SHY does not sell consumer health data. Consumer health data is shared only with service providers acting on SHY's instructions and only as needed to operate the service, and where you make information visible to other members by choosing to publish it on your profile.

SHY does not use third-party advertising or analytics trackers to collect consumer health data, and does not share consumer health data for cross-context behavioural advertising.

4. Third parties and affiliates with whom data is shared

Categories of third parties: cloud hosting and database providers; authentication providers; push-notification providers; error-monitoring providers; email delivery providers.

Specific affiliates: SHY Technologies LLC has no affiliates. Unresolved: Washington requires specific affiliates to be named; confirm this remains accurate at publication.

Nevada requires each named recipient to be accurate and current. This list must be reconciled against the live vendor inventory before this page is published, and re-checked whenever a vendor changes.

5. How consumer health data is processed

Consumer health data is stored in access-controlled databases, restricted by row-level security so that a member's data is reachable only by that member and by authorised SHY systems. It is processed to provide the features you use — profile presentation, discovery and matching, verification, and safety review — and is not processed for advertising.

6. Your rights, and how to exercise them

How to make a request: email [email protected] with the subject “Consumer Health Data Request,” or use the privacy tools in the app. Include the email address on your account so we can locate it. SHY will verify that a request comes from you or an authorised agent before acting on it.

Response time and appeal: Unresolved — must state the response window and the appeal route before publication.

7. Consent

SHY requests two separate consents, neither of which is bundled into acceptance of the Terms of Service: one to collect consumer health data beyond what is necessary to provide the service you requested, and a separate consent to share it. Each may be withdrawn at any time without affecting the lawfulness of processing before withdrawal.

Unresolved. This statement describes a required design, not a shipped one. Two distinct, unbundled opt-in consents must exist in the product before this paragraph can be published — Washington expressly invalidates consent bundled into terms acceptance, or inferred from hovering, pausing, or dismissing a dialog.

8. Changes to this policy

If SHY makes a material change to this policy, it will post the updated policy at this address with a new effective date and notify affected members before the change takes effect for previously collected data. Prior versions will be made available on request.

Contact

Privacy requests and questions.

SHY Technologies LLC, 5310 Martin Luther King Blvd, Kinloch, Missouri 63140.